Usable with caveats: the release is licensed, documented, tested in its repository, and clearly backed by a matching source project. Maintenance has recently slowed to no commits or merged pull requests in three months, and several workflows grant write access or use pull-request targeting.
68%
Total Score
67
100
94
75
One of four workflows uses pull_request_target, although no untrusted checkouts or script-injection patterns were detected. The workflow design deserves review because pull-request-target jobs can carry elevated trust implications.
The package has six releases over about 694 days, with two releases in the last 12 months and a median interval of about 120 days. This is established but not especially rapid maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Although v2.0.2 was released recently, this lack of current development activity is a meaningful maintenance concern.
There is only one open issue and three open pull requests, but none were opened or merged during the last month. This indicates limited recent repository activity without showing severe abandonment.
Three workflows declare top-level write permissions and one workflow lacks top-level permissions entirely. Broad write access increases workflow-maintenance risk compared with narrowly scoped permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.